http://www.huffingtonpost.in/2015/02/24/mcafee-labs-threat-report_n_6748430.html


18 Of 25 Popular Mobile Apps Vulnerable To Attacks: McAfee

PTI

Posted: 25/02/2015 07:29 IST Updated: 25/02/2015 07:29 IST

[image: http://s.huffpost.com/images/social/pin_icon_onhover.png]
<http://www.pinterest.com/pin/create/button/?url=http%3A%2F%2Fwww.huffingtonpost.in%2F2015%2F02%2F24%2Fmcafee-labs-threat-report_n_6748430.html&media=http%3A%2F%2Fi.huffpost.com%2Fgen%2F1777767%2Fthumbs%2Fn-NAVER-large570.jpg&description=18%20Of%2025%20Popular%20Mobile%20Apps%20Vulnerable%20To%20Attacks:%20McAfee>[image:
NAVER]

A model holds an Apple Inc. iPhone 5s displaying an application for Line
Corp.'s internet messaging and calling service, controlled by Naver Corp.,
in an arranged photograph in Hong Kong, China, on Tuesday, Feb. 25, 2014.
SoftBank Corp. is seeking to buy a stake in Line, people with knowledge of
the matter said. Photographer: Brent Lewin/Bloomberg via Getty Images |
Bloomberg via Getty Images

New Delhi — Cellphones with mobile apps could be potential target of cyber
attacks globally and subscribers' data including usernames and passwords
are at risk, security software maker McAfee said today.

The failure of mobile application developers to patch critical secure
sockets layer (SSL) vulnerabilities could potentially impact millions of
mobile phone users, according to McAfee Labs Threats Report: February 2015.

It said that in September 2014, Computer Emergency Response Team (CERT) at
Carnegie Mellon University released a list of vulnerable mobile
applications and McAfee Labs in January tested the 25 most popular apps on
the list.

During the tests, it was found that 18 have still not been patched despite
public disclosure, vendor notification, and, in some cases, multiple
version updates addressing concerns other than security.

The report said most downloaded vulnerable app in this group is a mobile
photo editor with between 100 million and 500 million downloads. The app
allows users to share photos on several social networks and cloud services.

"McAfee Labs researchers simulated man-in-the-middle (MITM) attacks that
successfully intercepted information shared during supposedly secure SSL
sessions. The vulnerable data included usernames and passwords and in some
instances, login credentials from social networks and other third party
services," it said.

Although there is no evidence that these mobile apps have been exploited,
the cumulative number of downloads for these apps ranges into the hundreds
of millions, the report said. "Given these numbers, McAfee Labs findings
suggest that the choice by mobile app developers to not patch the SSL
vulnerabilities has potentially put millions of users at risk of becoming
targets of MITM attacks," it added.

McAfee Labs also warned of increasingly aggressive potentially unwanted
programs (PUPs) that change system settings and gather personal information
without the knowledge of users.

McAfee Labs reported that mobile malware samples grew 14 per cent during
the fourth quarter of 2014, with Asia and Africa registering the highest
infection rates.




__._,_.___
 ------------------------------
Posted by: "beowulf" <[email protected]>
------------------------------


 Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmM2tjZDNwBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0MjQ4OTg1NjY->

   - New Members
   
<https://groups.yahoo.com/neo/groups/grendelreport/members/all;_ylc=X3oDMTJnc2ZmZ2xuBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2bWJycwRzdGltZQMxNDI0ODk4NTY2>
   1

 [image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJlczNoM2FpBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQyNDg5ODU2Ng-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to